CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-14630
3.1 LOW

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/memory/langchain/code/smart_customer_service.py of the component Memory …

Jul 4, 2026
CVE-2026-14629
4.3 MEDIUM

A flaw has been found in RT-Thread up to 5.2.2. Affected is the function read/write/sys_ioctl of the file components/lwp/lwp_syscall.c of the component Parameter Handler. Executing …

Jul 4, 2026
CVE-2026-14535
8.8 HIGH

In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless …

Jul 4, 2026
CVE-2026-14534
8.8 HIGH

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS …

Jul 4, 2026
CVE-2026-14628
5.3 MEDIUM

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. …

Jul 4, 2026
CVE-2026-14627
5.6 MEDIUM

A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord …

Jul 4, 2026
CVE-2025-13475
3.5 LOW

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS …

Jul 4, 2026
CVE-2026-53362

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch …

Jul 4, 2026
CVE-2026-53361

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with …

Jul 4, 2026
CVE-2026-53360

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the …

Jul 4, 2026
CVE-2026-53359

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix …

Jul 4, 2026
CVE-2026-14626
4.3 MEDIUM

A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component …

Jul 4, 2026
CVE-2026-14625
6.3 MEDIUM

A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation …

Jul 4, 2026
CVE-2026-12196

HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management …

Jul 4, 2026
CVE-2026-12195

myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when …

Jul 4, 2026
CVE-2026-14624
4.3 MEDIUM

A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. The …

Jul 4, 2026
CVE-2026-14623
4.3 MEDIUM

A vulnerability was determined in omec-project amf up to 2.1.1. This issue affects the function RRCInactiveTransitionReport of the component NGAP Message Handler. Executing a manipulation …

Jul 4, 2026
CVE-2026-14622
7.3 HIGH

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing …

Jul 4, 2026
CVE-2026-14621
3.1 LOW

A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of the component OSX Broker. …

Jul 4, 2026
CVE-2026-14619
6.3 MEDIUM

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /medicine.php. This manipulation …

Jul 4, 2026
CVE-2026-12194

PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the …

Jul 4, 2026
CVE-2026-14618
4.3 MEDIUM

A vulnerability was detected in Open5GS up to 2.7.7. Affected by this vulnerability is the function amf_nnrf_handle_nf_discover of the file src/amf/nnrf-handler.c of the component AMF. …

Jul 4, 2026
CVE-2026-12252
7.8 HIGH

In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes …

Jul 4, 2026
CVE-2025-71380
8.8 HIGH

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or …

Jul 4, 2026
CVE-2025-71375
8.1 HIGH

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller …

Jul 4, 2026
CVE-2025-71373
8.1 HIGH

picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads …

Jul 4, 2026
CVE-2025-71372
8.1 HIGH

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute …

Jul 4, 2026
CVE-2025-71369
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed …

Jul 4, 2026
CVE-2025-71367
8.1 HIGH

picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files …

Jul 4, 2026
CVE-2025-71366
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code …

Jul 4, 2026
CVE-2025-71364
8.1 HIGH

picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this …

Jul 4, 2026
CVE-2025-71362
8.1 HIGH

picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that …

Jul 4, 2026
CVE-2025-71360
8.1 HIGH

picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes …

Jul 4, 2026
CVE-2025-71359
8.1 HIGH

picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files …

Jul 4, 2026
CVE-2025-71356
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that executes remote code …

Jul 4, 2026
CVE-2025-71353
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that …

Jul 4, 2026
CVE-2025-71347
8.1 HIGH

picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed …

Jul 4, 2026
CVE-2025-71345
8.1 HIGH

picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, …

Jul 4, 2026
CVE-2025-71343
8.1 HIGH

picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded …

Jul 4, 2026
CVE-2025-71342
8.1 HIGH

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during …

Jul 4, 2026
CVE-2026-54424
8.4 HIGH

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through …

Jul 4, 2026
CVE-2026-58523
6.5 MEDIUM

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

Jul 3, 2026
CVE-2026-14617
3.1 LOW

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming …

Jul 3, 2026
CVE-2026-58597
4.3 MEDIUM

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-58524
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-58522
6.8 MEDIUM

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Jul 3, 2026
CVE-2026-58426
9.6 CRITICAL

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Jul 3, 2026
CVE-2026-58424
8.9 HIGH

Permanent Fork PR Workflow Approval Gate Bypass

Jul 3, 2026
CVE-2026-58423
7.7 HIGH

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Jul 3, 2026
CVE-2026-58422
9.8 CRITICAL

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Jul 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.